[Security] Restrict unserialize() allowed_classes in TaskProcessing distributed cache#60883
Open
XananasX7 wants to merge 1 commit into
Open
Conversation
getAvailableTaskTypes() stores a serialized array of ShapeDescriptor, ShapeEnumValue, and EShapeType values in the distributed cache and reads them back with bare unserialize() — no allowed_classes restriction. An attacker who can write to the distributed cache backend (e.g., via an unauthenticated Redis instance, SSRF to the cache server, or a cache-poisoning vulnerability) can inject a crafted PHP serialized payload containing a gadget chain and achieve Remote Code Execution when getAvailableTaskTypes() is next called. Restrict allowed_classes to the three value-object types actually stored in this cache entry (ShapeDescriptor, ShapeEnumValue, EShapeType). Any other class in the serialized string will become a harmless __PHP_Incomplete_Class without executing constructors or magic methods.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
TaskProcessing\Manager::getAvailableTaskTypes()serializesShapeDescriptor,ShapeEnumValue, andEShapeTypeobjects into the distributed cache and reads them back with bareunserialize()— noallowed_classesrestriction.An attacker who can write to the distributed cache backend can inject a crafted PHP serialized payload containing a gadget chain and achieve Remote Code Execution when
getAvailableTaskTypes()is next called.Attack scenario
__destruct/__wakeup).getAvailableTaskTypes()call, the gadget chain fires → RCE.Fix
Restrict
allowed_classesto the three value-object types that are actually stored in this cache entry (ShapeDescriptor,ShapeEnumValue,EShapeType). Any other class in the serialized string becomes a harmless__PHP_Incomplete_Class.Files changed
lib/private/TaskProcessing/Manager.php— add explicitallowed_classestounserialize()